Privacy

registry.falsify.dev · effective 2026-07-18 · controller: Cüneyt Öztürk (falsify.dev) · contact hello@falsify.dev

1 · The one rule that matters

Do not put personal data in a manifest. Not in producer.id, not in the optional handle, not anywhere. Receipts are public, content-addressed, independently timestamped and mirrored to the Rekor transparency log — erasure is technically impossible once committed. Identify as an organisation ("acme-evals") or a pseudonymous handle. The registry automatically rejects submissions whose identity fields look like an email address or phone number; everything subtler is your responsibility.

2 · What we process

Submitted content: the manifest bytes, their hash, a signed receipt, an RFC 3161 timestamp token — stored and public, treated as non-personal technical data.
IP addresses: used only for rate limiting; held in a counter that expires within 1 hour; never attached to receipts.
Page analytics: a first-party beacon stores host, path, referrer and country (no IP, no cookies, no fingerprint), retained up to 30 days.
No accounts, no cookies, no third-party trackers.

3 · Legal basis and your rights

Processing rests on legitimate interest (Art. 6(1)(f) GDPR): operating a public integrity log with the minimum data possible. For the transient data (rate-limit counters, analytics) you may request access or erasure at any time. For committed manifests, §1 applies: design-level immutability means the stored bytes can be unpublished from this service on request, but hashes already countersigned by external authorities cannot be recalled — which is why the front door refuses personal data in the first place. Complaints: your local data-protection authority; the controller operates from the EU (Estonia).